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Abstract 

A new framework for information hiding security, called topological-security, has 
been proposed in a previous study. It is based on the evaluation of unpredictability of 
the scheme, whereas existing notions of security, as stego-security, are more linked to 
information leaks. It has been proven that spread-spectrum techniques, a well-known 
stego-secure scheme, are topologically-secure too. In this paper, the links between the 
two notions of security is deepened and the usability of topological-security is clarified, 
by presenting a novel data hiding scheme that is twice stego and topological-secure. 
This last scheme has better scores than spread-spectrum when evaluating qualitative 
and quantitative topological-security properties. Incidentally, this result shows that 
the new framework for security tends to improve the ability to compare data hiding 
scheme. 
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1 Introduction 



Information hiding has recently become a major digital technology [6], [9], especially with 
the increasing importance and widespread distribution of digital media through the Internet. 
Spread-spectrum data-hiding techniques have been widely studied in recent years under the 
scope of security. These techniques encompass several schemes, such as Improved Spread 
Spectrum (ISS), Circular Watermarking (CW), and Natural Watermarking (NW). Some of 
these schemes have revealed various security issues. On the contrary, it has been proven 
in jl] that the Natural Watermarking technique is stego-secure. This stego-security is one of 
the security classes defined in jl]. In this paper, probabilistic models are used to categorize 
the security of data hiding algorithms in the Watermark Only Attack (WOA) framework. 

We will show that the security level of such algorithms can be studied into a novel 
framework based on unpredictability, as it is understood in the theory of chaos |5j. To do 
so, a new class of security will be introduced, namely the topological-security. This new 
class can be used to study some categories of attacks that are difficult to investigate in the 
existing security approach. It also enriches the variety of qualitative and quantitative tools 
that evaluate how strong the security is, thus reinforcing the confidence that can be had in 
a given scheme. 

In addition of being stego-secure, it has been proven in [3] that Natural Watermarking 
technique is topologically-secure. Moreover, this technique possesses additional properties of 
unpredictability, namely, strong transitivity, topological mixing, and a constant of sensitivity 
equal to y. However NW are not expansive, which is problematic in the Constant-Message 
Attack (CMA) and Known Message Attack (KMA) setups [3]. In this paper, it is proven 
by using the new topological-security framework, that a more secure scheme than NW can 
be found to withstand attacks in these setups. This scheme, introduced in [2], is based 
on the so-called chaotic iterations. The aim of this work is to prove that this algorithm is 
stego-secure and topologically-secure, to study its qualitative and quantitative properties of 
unpredictability, and then to compare it with Natural Watermarking. 

The rest of this paper is organized as follows. In Section [2j basic definitions and termi- 
nologies in the field of topology, chaos, and security are recalled. In Section [3] the stego- 
security of chaotic iterations is established in some cases, whereas in Section [4] is studied the 
topological-security of chaotic iterations. Natural Watermarking and chaotic iterations are 
then compared in Section |5j The paper ends with a conclusion where our contribution is 
summarized, and planned future work is discussed. 

2 Basic recalls 
2.1 Chaotic iterations 

In this section, the definition and main properties of chaotic iterations are recalled pp. 
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2.1.1 Chaotic iterations 



In the sequel S n denotes the n term of a sequence S and V{ the i component of a vector 
V. Finally, the following notation is used: [1; NJ — {1, 2, ... , N}. 

Let us consider a system of a finite number N of elements (or cells), so that each cell 
has a boolean state. A sequence of length N of boolean states of the cells corresponds to a 
particular state of the system. A sequence which elements belong to [1; N] is called a strategy. 
The set of all strategies is denoted by §. 

Definition 1 The set B denoting {0, 1}, let / : B N — ► B N be a function and S G § be a 
strategy. The so-called chaotic iterations are defined by x° G B N and V(n, i) G IN* x [1; N]: 



2.1.2 Devaney's chaotic dynamical systems 

Consider a metric space (X, d) and a continuous function f on X. f is said to be topologically 
transitive if, for any pair of open sets U,V C X, there exists k > such that f h {U) n V ^ 0. 
(X, /) is said to be regular if the set of periodic points is dense in X. f has sensitive 
dependence on initial conditions if there exists 5 > such that, for any x G X and any 
neighborhood V of x, there exists y & V and n ^ such that |/ n (x) — f n (y)\ > 5. 5 is called 
the constant of sensitivity of /. Quoting Devaney in [5], 

Definition 1 A function / : X — > X is said to be chaotic on X if (X, f) is regular, 
topologically transitive and has sensitive dependence on initial conditions. 

2.1.3 Chaotic iterations and Devaney's chaos 

In this section we give outline proofs of the properties on which our secure data hiding 
scheme is based. The complete theoretical framework is detailed in pQ. 

Denote by A the discrete boolean metric, A(x, y) = <^ x = y. Given a function /, define 



Let us consider the phase space X = [1; N] M xB N and the map Gf (S, E) = (a(S), F f (i(S), E)), 
where a is defined by a : (S n ) ne n$ G § — > (S n+1 ) ne t( G §, and % is the map % : (S n ) ne ^ G § — > 
S° G [1; N]. So the chaotic iterations can be described by the following iterations: 




the function: F f : [1; N]xB 




X° G X and X k+1 = G f (X k ). 



We have defined in pQ a new distance d between two points (S,E),(S,E) G X by 
d((S, E); (S, E)) = d e (E, E) + d s (S, S), where: 



N 



k=l 
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It is then proven that, 
Proposition 1 Gf is a continuous function on (X,d). 

In the metric space (X,d), the vectorial negation f : M N — > M N , (61, • • • , &n) 1 — > 
(&!,••• ,&n) satisfies the three conditions for Devaney's chaos: regularity, transitivity, and 
sensitivity pQ. So, 

Proposition 2 Gf is a chaotic map on (X, d) according to Devaney. 

2.2 Using chaotic iterations as information hiding schemes 
2.2.1 Presentation of the scheme 

We have proposed in [2] to use chaotic iterations as an information hiding scheme, as follows 
(see Figure [T]). Let: 

• (K, N) G [0; 1] x IN be an embedding key, 

• X G B N be the N least significant coefficients (LSCs) of a given cover media C, 

• (5 n ) ne ]N G [1, N] M be a strategy, which depends on the message to hide M G [0; 1] and 
K, 

• fo : B N — 7- B N be the vectorial logical negation. 




(a) Original Lena. (b) Watermarked Lena. 

Figure 1: Data hiding with chaotic iterations 

So the watermarked media is C whose LSCs are replaced by Yk = X , where: 

r x° = x 

\ < N, X n+1 = G fo (X n ) . 
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In the following section, two ways to generate (S n ) n& ^ are given, namely Chaotic It- 
erations with Independent Strategy (CIIS) and Chaotic Iterations with Dependent Strat- 
egy (CIDS). In CIIS, the strategy is independent from the cover media X, whereas in CIDS 
the strategy will be dependent on X. Their stego-security are studied in Section [3] and their 
topological-security in Section |4| 



2.2.2 Examples of strategies 

CIIS strategy Let us first introduce the Piecewise Linear Chaotic Map (PLCM, see [7]), 
defined by: 

Definition 2 (PLCM) 

{x/p if x G [0;p] 

(x-p)/(\ -p) if x G [p; \] 
F(l — x,p) else. 

where p G ] 0; \ [ is a "control parameter" . 

Then, we can define the general term of the strategy (S n ) n in CIIS setup by the following 
expression: S n = [N x K n \ + 1, where: 

p G [0; |] 
K° = M <g) K 
K n+i = F(K n ,p),\/n < N 

in which ® denotes the bitwise exclusive or (XOR) between two floating part numbers (i.e., 
between their binary digits representation). Lastly, to be certain to enter into the chaotic 
regime of PLCM [7j, the strategy can be preferably defined by: S n = |_N x K n+D \ + 1, where 

Del. 

CIDS strategy The same notations as above are used. We define CIDS strategy as follows: 
VA; < N, 

• if k < N and X k = 1, then S k = k, 

• else S k = 1. 

In this situation, if iV ^ N, then only two watermarked contents are possible with the scheme 



proposed in Section 2.2, namely: Y K = (0, 0, • • • , 0) and Y% = (1, 0, • • • , 0). 



3 Evaluation of the stego-security 
3.1 Definition of stego-security 

Stego-security, defined in the Simmons' prisoner problem j8], is the highest security class in 
WOA setup @]. 
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Let K be the set of embedding keys, p(X) the probabilistic model of N initial host 
contents, and p{Y\K\) the probabilistic model of N Q watermarked contents. We suppose 
that each host content has been watermarked with the same key K\ and the same embedding 
function e. 

Definition 3 The embedding function e is stego-secure if and only if: 

VK 1 GK,p(Y|K 1 ) = p(X) 

3.2 Evaluation of the stego-security 

Let us now study the stego-security of the scheme. We will prove that, 
Proposition 3 CIIS are stego-secure. 

Proof Let us suppose that X ~ U (M N ) in a CIIS setup. We will prove by a math- 
ematical induction that Wn G IN, X n ~ U (B^) . The base case is immediate, as X° = 
X ~ U (B^) . Let us now suppose that the statement X n ~ U (B^) holds for some 
n. Let e G M N and B fc = (0, • • • , 0, 1, 0, • • • , 0) G M N (the digit 1 is in position k). So 
P (X n+1 = e) = J2k=i P(X n = e + B k ,S n = k). These two events are independent in CIIS 
setup, thus: P (X n+1 = e) = J2k=i P(X n = e + B k ) x P (S n = k). According to the in- 
ductive hypothesis: P (X n+1 = e) = ± J2k=i P ( 5 ™ = k )- The set of events i Sn = k ) for 
k G [1; N\ is a partition of the universe of possible, so Ylk=i P (^ n — k) — 1. 

Finally, P (X n+1 = e) = ^, which leads to X n+1 ~ U (B^). This result is true Wn G IN, 
we thus have proven that, 

VK G [0; 1],Y K = X No ~ U (B^) when X ~ U (B^) 

So CIIS defined in Section |2.2| are stego-secure. 

We will now prove that, 
Proposition 4 CIDS are not stego-secure. 

Proof Due to the definition of CIDS, we have P(Y K = (1, 1, • • • , 1)) = 0. So there is no 
uniform repartition for the stego-contents Yk- 

4 Evaluation of the topological-security 
4.1 Definition 

To check whether an information hiding scheme 5* is topologically-secure or not, S must be 
written as an iterate process x n+1 = f(x n ) on a metric space (X,d). This formulation is 
always possible, as it is proven in So, 
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Definition 4 An information hiding scheme S is said to be topologically-secure on [X, d) 
if its iterative process has a chaotic behavior according to Devaney. 

It can be established that, 
Proposition 5 CIIS and CIDS are topologically-secure. 

Proof It has been proven in |TJ that chaotic iterations have a chaotic behavior, as defined 
by Devaney. 

In the two following sections, we will study the qualitative and quantitative properties 
of topological-security for chaotic iterations. These properties can measure the disorder 
generated by our scheme, giving by doing so some important informations about the unpre- 
dictability level of such a process. 

4.2 Quantitative property of chaotic iterations 

Definition 5 (Expansivity) A function / is said to be expansive if 3e > 0, Vx ^ y, 3n G 

w,d(f n (x),r(y))>e. 

Proposition 6 Gf is an expansive chaotic dynamical system on X with a constant of ex- 
pansivity is equal to 1. 

Proof If (S, E) ^ (£>; E), then either E ^ E, so at least one cell is not in the same state 
in E and E. Consequently the distance between (S, E) and (S; E) is greater or equal to 1. 
Or E = E. So the strategies S and S are not equal. Let no be the first index in which the 
terms S and S differ. Then V/c < n , G k fo (S, E) = G k fo (S, E), and G™ (^, E) ^ G n f °(S, E). As 
E = E, the cell which has changed in E at the n -th iterate is not the same as the cell which 
has changed in E, so the distance between G^°(S, E) and G^°(S, E) is greater or equal to 2. 

4.3 Qualitative property of chaotic iterations 

Definition 6 (Topological mixing) A discrete dynamical system is said to be topologi- 
cally mixing if and only if, for any couple of disjoint open set U, V ^ 0, no g IN can be found 
so that Vn ^ n , f n (U) n V ^ 0. 

Proposition 7 Gf is topologically mixing on (X',d'). 

This result is an immediate consequence of the lemma below. 
Lemma 1 For any open ball B of X' , an index n can be found such that G 1 } (B) = X' . 

Proof Let B = B((E, S),e) be an open ball, which the radius can be considered as strictly 
less than 1. All the elements of B have the same state E and are such that an integer 
k{= — log 10 (e)) satisfies: 
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• all the strategies of B have the same k first terms, 

• after the index k, all values are possible. 

Then, after k iterations, the new state of the system is G*j o (E,S)i and all the strategies 
are possible (all the points (G^E, S)i,S), with any S G §, are reachable from B). 

We will prove that all points of X' are reachable from B. Let (E', S') G X' and Si be 
the list of the different cells between G^ Q (E,S)i and E' . We denote by \s\ the size of the 
sequence Sj. So the point (E, S) of B defined by: E = E, S l = S\Vi ^ k, S k+l = Sj, Vz ^ |s|, 
and Vi G IN, S*+M-* = S rt is such that Gj+ W (£, 5) = (£", 5'). This concludes the proofs of 
the lemma and of the proposition. 

5 Comparison between spread-spectrum and chaotic 
iterations 

The consequences of topological mixing for data hiding are multiple. Firstly, security can 
be largely improved by considering the number of iterations as a secret key. An attacker 
will reach all of the possible media when iterating without this key. Additionally, he cannot 
benefit from a KOA setup, by studying media in the neighborhood of the original cover. 
Moreover, as in a topological mixing situation, it is possible that any hidden message (the 
initial condition), is sent to the same fixed watermarked content (with different numbers of 
iterations), the interest to be in a KMA setup is drastically reduced. Lastly, as all of the 
watermarked contents are possible for a given hidden message, depending on the number of 
iterations, CMA attacks will fail. 

The property of expansivity reinforces drastically the sensitivity in the aims of reducing 
the benefits that Eve can obtain from an attack in KMA or KOA setup. For example, it is 
impossible to have an estimation of the watermark by moving the message (or the cover) as 
a cursor in situation of expansivity: this cursor will be too much sensitive and the changes 
will be too important to be useful. On the contrary, a very large constant of expansivity 
e is unsuitable: the cover media will be strongly altered whereas the watermark would be 
undetectable. 

Finally, spread-spectrum is relevant when a discrete and secure data hiding technique 
is required in WOA setup. However, this technique should not be used in KOA and KMA 
setup, due to its lack of expansivity. schemes, which are expansive. 

6 Conclusion and future work 

In this paper, the links between stego-security and topological-security has been deepened. 
The information hiding scheme presented in [2], which is based on chaotic iterations, has 
been recalled and its level of security has been studied. It has been proven that this algo- 
rithm is twice stego and topologically-secure. This was already the case for spread-spectrum 
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techniques, as it has been established in [3]. Moreover, as for spread-spectrum, chaotic iter- 
ations possess the qualitative property of topological mixing, which are useful to withstand 
attacks. However, unlike spread-spectrum, chaotic iterations are expansive, so this scheme is 
better than spread-spectrum in KOA and KMA setups. Incidentally, this result shows that 
the new framework for security tends to improve the ability to compare data hiding scheme. 
In future work, we will give a better understanding of the links between these two security 
frameworks. Additionally, the comparison between spread-spectrum and chaotic iterations 
outlined in this paper will be extended. The security of other existing schemes will be studied 
in the framework of topological-security. Last, but not least, the way to understand these 
new tools in terms of data hiding aims will be enhanced: this study is required to make 
topological-security framework truly useful in practice. 
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